Skip to main navigation Skip to search Skip to main content

Demystifying OpenZeppelin’s Own Vulnerabilities and Analyzing Their Propagation in Smart Contracts

  • Han LIU
  • , Daoyuan WU*
  • , Yuqiang SUN
  • , Shuai WANG
  • , Yang LIU
  • , Yixiang CHEN
  • *Corresponding author for this work

Research output: Book Chapters | Papers in Conference ProceedingsConference paper (refereed)Referred Conference Paperpeer-review

Abstract

OpenZeppelin is a building block for many smart contracts on Ethereum-compatible blockchains. It provides mod-ular and reusable libraries for various Ethereum standards (e.g., ERC20 and ERC721) and common functionalities such as upgradeable contracts. Little research has been done on Open-Zeppelin security except for a recent study, which focused only on the misuse of OpenZeppelin code, assuming OpenZeppelin itself is secure but contract developers may not follow OpenZeppelin’s function checks appropriately. We argue that, despite appearing robust, OpenZeppelin itself could have many vulnerabilities, and these library-level vulnerabilities could inadvertently affect third-party smart contracts, even without misuse from developers.We present ZepCompare, the first end-to-end system for demystifying OpenZeppelin’s own vulnerabilities and analyzing their propagation in third-party smart contracts. ZepCompare incorporates a manual analysis stage where we review OpenZeppelin’s 64 historical releases, identifying 109 vulnerable-fixed code pairs, exposing flaws in cryptographic utilities, access control, etc. Leveraging these pairs, ZepCompare introduces facts of changes, a novel structure capturing vulnerable and fixed code contexts for flexible matching. Evaluated across 88,605 contracts from three Ethereum-compatible chains, ZepCompare detects 4,708 instances of OpenZeppelin-derived vulnerabilities. Manual sampling and a ground-truth experiment confirm that ZepCompare achieves 86.7% precision and 77.1% recall. Our findings reveal significant security risks in both historical and the latest versions of OpenZeppelin libraries, underscoring the urgent need for systematic auditing of foundational contracts components.
Original languageEnglish
Title of host publicationProceedings - 2025 40th IEEE/ACM International Conference on Automated Software Engineering, ASE 2025
PublisherIEEE
Pages945-957
Number of pages13
ISBN (Electronic)9798350357332
DOIs
Publication statusPublished - Nov 2025
Event2025 40th IEEE/ACM International Conference on Automated Software Engineering - Seoul, Korea, Republic of
Duration: 16 Nov 202520 Nov 2025

Publication series

NameIEEE/ACM International Conference on Automated Software Engineering
PublisherIEEE
ISSN (Print)1938-4300
ISSN (Electronic)2643-1572

Conference

Conference2025 40th IEEE/ACM International Conference on Automated Software Engineering
Abbreviated titleASE 2025
Country/TerritoryKorea, Republic of
CitySeoul
Period16/11/2520/11/25

Bibliographical note

Publisher Copyright:
© 2025 IEEE.

Funding

We thank all reviewers for their constructive comments. This research is partially supported by a research fund provided by HSBC, HKUST TLIP Grant FF612, and Lingnan Grant SUG- 002/2526. This research is also supported by the National Research Foundation, Singapore, and DSO National Laboratories under the AI Singapore Programme (AISG Award No: AISG4- GC-2023-008-1B); by the National Research Foundation Singapore and the Cyber Security Agency under the National Cybersecurity R&D Programme (NCRP25-P04-TAICeN); and by the Prime Minister's Office, Singapore under the Campus for Research Excellence and Technological Enterprise (CREATE) Programme. Any opinions, findings and conclusions, or recommendations expressed in these materials are those of the author(s) and do not reflect the views of the National Research Foundation, Singapore, Cyber Security Agency of Singapore, Singapore.

Keywords

  • OpenZeppelin Library
  • Smart Contracts
  • Vulnerability Propagation
  • Vulnerability Detection

Fingerprint

Dive into the research topics of 'Demystifying OpenZeppelin’s Own Vulnerabilities and Analyzing Their Propagation in Smart Contracts'. Together they form a unique fingerprint.

Cite this